CVE-2026-4092Disclosure(google / clasp)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch google clasp systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Path Traversal in Clasp impacting versions < 3.2.0 allows a remote attacker to perform remote code execution via a malicious Google Apps Script project containing specially crafted filenames with directory traversal sequences.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • clasp

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-15); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
clasp

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-03-13: 2Mentions · 2026-03-14: 1Mentions · 2026-03-15: 3Mentions · 2026-03-16: 1PoC Mentioned / Linked · 2026-03-13: 1PoC Mentioned / Linked · 2026-03-15: 1Patch / Workaround · 2026-03-13: 1Patch / Workaround · 2026-03-15: 1Technical Details · 2026-03-13: 2Technical Details · 2026-03-14: 1Technical Details · 2026-03-15: 1Technical Details · 2026-03-16: 103-1303-1403-1503-16
Signal classification2 categories
Disclosure
685.7%
General
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-132
Disclosure1General1
2026-03-141
Disclosure1
2026-03-153
Disclosure3
2026-03-161
Disclosure1
Full discourse7 posts
  • Gouri Sankar A@g0w6y
    Disclosure

    @cyberbivash Thanks for covering this! I'm the researcher who discovered and reported CVE-2026-4092. http://github.com/g0w6y/CVE-2026-4092

    Post summary

    The researcher announces their discovery of CVE-2026-4092 and links to a GitHub repository that likely contains the vulnerability details or PoC.

    0001037
    4 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4092 Path Traversal in Clasp impacting versions &lt; 3.2.0 allows a remote attacker to perform remote code execution via a malicious Google Apps Script project containing speci… https://www.cve.org/CVERecord?id=CVE-2026-4092

    Post summary

    The post announces a Path Traversal vulnerability in Clasp versions < 3.2.0 that enables remote code execution via a malicious Google Apps Script.

    1000087
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4092 - Google Apps Script Path Traversal Remote Code Execution Vulnerability Intel Report: https://ift.tt/8dRhxmG

    Post summary

    The notice identifies CVE-2026-4092 as a path‑traversal RCE in Google Apps Script and points to an external intel report, but provides no proof of exploitation, PoC, patch, or other actionable details.

    1000042
    340 followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-4092 - Malicious Google Apps Script projects with crafted filenames can enable remote code execution. Tier: T1 – High Arsenal Value Full Analysis: https://lnkd.in/ezQENJrr #CyberSecurity #AppSec #DevSecOps #CVE #RemoteCodeExecution #ThreatIntelligence

    Post summary

    The tweet announces CVE‑2026‑4092 as a remote code execution flaw in Google Apps Script driven by crafted filenames, indicating high threat potential but providing no PoC, exploit, or patch details.

    0000061
    42 followersView on X
  • Gouri Sankar A@g0w6y
    Disclosure

    @CVEnew Thanks! I discovered and reported this vulnerability. http://github.com/g0w6y/CVE-2026-4092

    Post summary

    The user announces they discovered and reported CVE‑2026‑4092, linking to a GitHub repository, but no further technical or exploit details are provided.

    0000037
    4 followersView on X
  • Gouri Sankar A@g0w6y
    Disclosure

    Just got my first CVE! 🔐 CVE-2026-4092 — Path Traversal in @google/clasp High severity — CVSS v4: 8.7 Arbitrary file write via malicious GAS project. Discovered, reported &amp; fixed. Patched in v3.2.0. - Affected: &lt; 3.2.0 - Patched: v3.2.0 http://nvd.nist.gov/vuln/detail/CVE-2026-4092 #CVE https://t.co/jXdaL4ZJLH

    Post summary

    A newly disclosed path traversal vulnerability (CVE-2026-4092) in @google/clasp is high severity, has been fixed in v3.2.0, and patch information is provided.

    0000062
    4 followersView on X
  • dbugs@ptdbugs
    Disclosure

    Arbitrary File Write via Path Traversal in Google clasp leading to RCE CVE: CVE-2026-4092 Vendor: Google Product: Clasp CVSS: 8.7 Credits: n/a Description: Path Traversal in Clasp impacting versions < 3.2.0 allows a remote attacker to perform remote code execution via a malicious Google Apps Script project containing specially crafted filenames with directory traversal sequences. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-4092 • https://github.com/google/clasp/pull/1109 #dbugs_vuln

    Post summary

    CVE‑2026‑4092 is a path‑traversal flaw in Google Clasp (<3.2.0) that enables RCE; vendor has released a patch via pull request and a public vulnerability page with details.

    0000065
    592 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgoogleclasp---

Explore more